CVE-2025-2526

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 8, 2025
CWE ID 639

Summary

CVE-2025-2526 is a privilege escalation vulnerability affecting the Streamit theme for WordPress. The issue arises from the theme's failure to verify user identities before updating their email addresses in the 'st_Authentication_Controller::edit_profile' function. As a result, unauthenticated attackers can manipulate email addresses for any user, including administrators, ultimately leading to account takeover. This allows attackers to reset passwords and gain administrator access, posing a significant security risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share